Hallmark cards scam warning

Permabanned
Joined
24 Jul 2005
Posts
15,697
Location
R'lyeh
Just checked my Googlemail and found that I'd apparently I'd recieved a Hallmark E-Card from someone. Check out the status bar at the bottom though when I hover the mouse over the link to "see the sard"!

gcs0072lo1.jpg


I don't know if it's a genuine thing or, probably the more likely outcome, a virus of some description. Just make sure that any of your family and friends who aren't that tech savvy not to click on this.
 
Not bad, looks pretty genuine.

Usually it tells you which email its come from, but as it dosnt id spam it, get rid completely.
 
isn't @hallmark.com legit though? Obviously the attached ecard does look virusy form the name, but the email sender looks legit? :/
 
It's trivial to spoof a sender's email address because there was never any validation built-in to verify that who you say you are is actually who you are... i.e. I can easily spoof a mail to look like it was sent by [email protected] but the mail wouldn't have originated from labour.gov.uk and isn't verified at any stage along the process. All it takes is an open relay and you can impersonate anyone you want to.
 
Last edited:
It's trivial to spoof a sender's email address because there was never any validation built-in to verify that who you say you are is actually who you are
Although such a check has since been added. Its called SPF checking, but it requires that both the domain being spoofed and the mail server that receives the email is using it. In this case, Hallmark.com do have SPF records set up but it appears google have not checked them.

All it takes is an open relay and you can impersonate anyone you want to.
An open relay or just some software to send it directly, which is included in every Linux distribution and on some of the server versions of Windows, and can be added to any Windows PC.

What a lot of people probably don't realise is that this sort of email is usually sent from a normal home user's PC without them even knowing, because someone will infect them and then use them to send spam out.

Theres probably even someone reading this thread that is sending out hundreds of spams as we speak.
 
And this is why some ISP's now block or intercept outgoing traffic on port 25 to try and prevent spammers or infected machines sending spam.
 
Back
Top Bottom